Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rax40 Firmware CRITICAL 9.8
CVE-2022-48196

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, …

Fix: 1.0.2.60 / 1.0.4.122+
Fix from $2,300 2022-12-30
Wnr2000 Firmware HIGH 8.1
CVE-2022-46423

An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle)…

Fix: after 1.2.3.7
Fix from $1,950 2022-12-20
Xwn5001 Firmware HIGH 8.1
CVE-2022-46424

An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a M…

Fix: after 0.4.1.1
Fix from $1,950 2022-12-20
Rax30 Firmware HIGH 7.8
CVE-2022-47210

The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, ap…

Fix: 1.0.9.90+
Fix from $1,950 2022-12-16
Nighthawk Ax1800 Firmware HIGH 8.8
CVE-2022-47208

The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated atta…

Fix: 1.0.9.90+
Fix from $1,950 2022-12-16
Rax30 Firmware HIGH 8.8
CVE-2022-47209

A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and …

Fix: 1.0.9.90+
Fix from $1,950 2022-12-16
Ax2400 Firmware CRITICAL 10.0
CVE-2022-4390

A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interf…

Fix: 1.0.9.90+
Fix from $2,300 2022-12-09
R7000p Firmware CRITICAL 9.8
CVE-2022-44184

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44197

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44198

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44199

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44200

Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44194

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.

Mitigation only
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44191

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44193

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44196

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44186

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44187

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44188

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

No fix yet
Fix from $2,300 2022-11-22
R7000p Firmware CRITICAL 9.8
CVE-2022-44190

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

No fix yet
Fix from $2,300 2022-11-22
R6220 Firmware HIGH 8.8
CVE-2022-42221

Netgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability.

No fix yet
Fix from $1,950 2022-10-17
Wnr2000v4 Firmware CRITICAL 9.8
CVE-2022-37232

Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcp…

Mitigation only
Fix from $2,300 2022-09-23
R7000 Firmware CRITICAL 9.8
CVE-2022-37235

Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmwar…

Mitigation only
Fix from $2,300 2022-09-23
Wnr2000v4 Firmware CRITICAL 9.8
CVE-2022-31937

Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

Mitigation only
Fix from $2,300 2022-09-22
R7000 Firmware HIGH 7.8
CVE-2022-37234

Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmwar…

Mitigation only
Fix from $1,950 2022-09-22
Wpn824ext Firmware HIGH 7.5
CVE-2022-38955

An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack…

Mitigation only
Fix from $1,950 2022-09-20
Wpn824ext Firmware MEDIUM 5.3
CVE-2022-38956

An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to…

Fix: after 1.1.1_1.1.9
Fix from $1,600 2022-09-20
R6200 HIGH 8.8
CVE-2022-30079EPSS 25%

Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow …

Mitigation only
Fix from $1,950 2022-09-08
R8000 Firmware CRITICAL 9.8
CVE-2021-34236

Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sen…

Mitigation only
Fix from $2,300 2022-09-08
R6200 Firmware HIGH 8.8
CVE-2022-30078

NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote au…

Fix: after 1.0.4.52_10.0.93
Fix from $1,950 2022-09-07